CVE-2024-13484: Openshift-gitops-operator-container: namespace isolation break
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.
Other sources
Currently argocd applies the label openshift.io/cluster-monitoring to all namespaces that deploy a ArgoCD CR instance. This then allows the namespace to create a rogue PrometheusRule that can then have adverse effects on the platform monitoring stack. As the label is applied the rule is rolled out cluster wide.
This gives anyone who has argocd instances deployed a way to escalate out of their namespace isolation and affect the entire cluster.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13484?
CVE-2024-13484 has been assessed as a medium severity vulnerability due to its potential to affect platform monitoring.
How do I fix CVE-2024-13484?
To mitigate CVE-2024-13484, update ArgoCD to version 2.10.4 or later, which addresses this vulnerability.
What impact does CVE-2024-13484 have on ArgoCD?
CVE-2024-13484 can allow the creation of rogue PrometheusRules in namespaces, negatively impacting monitoring capabilities.
Is CVE-2024-13484 exploitable in all deployments of ArgoCD?
CVE-2024-13484 is exploitable in all deployments of ArgoCD versions up to and including 2.10.3.
What software versions are affected by CVE-2024-13484?
CVE-2024-13484 affects ArgoCD versions up to and including 2.10.3.